<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Webauth and Webadmin certificates fail to install on a WLC 5520 in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/3322355#M112424</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have two certificates (Webauth and Webadmin), created using the WLC's CSR. Both fail to install. Both will TFTP onto the WLC fine using the&amp;nbsp;Upload command on the GUI&amp;nbsp;but fail to install.&lt;/P&gt;
&lt;P&gt;The logs show: %UPDATE-3-CERT_INST_FAIL: updcode.c:1276 Failed to install Webauth certificate. rc = 1&lt;/P&gt;
&lt;P&gt;The certificates were created by different authorities (internal CA and Digicert)&lt;/P&gt;
&lt;P&gt;Both are .crt format. I have tried converting to PEM, this ends up as .cer format.&lt;/P&gt;
&lt;P&gt;The common names (CN) are the hostname of the WLC&lt;/P&gt;
&lt;P&gt;The WLC is in an SSO HA pair and running 8.3.133.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any pointers much appreciated&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 15:11:28 GMT</pubDate>
    <dc:creator>ashmead123</dc:creator>
    <dc:date>2021-07-05T15:11:28Z</dc:date>
    <item>
      <title>Webauth and Webadmin certificates fail to install on a WLC 5520</title>
      <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/3322355#M112424</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have two certificates (Webauth and Webadmin), created using the WLC's CSR. Both fail to install. Both will TFTP onto the WLC fine using the&amp;nbsp;Upload command on the GUI&amp;nbsp;but fail to install.&lt;/P&gt;
&lt;P&gt;The logs show: %UPDATE-3-CERT_INST_FAIL: updcode.c:1276 Failed to install Webauth certificate. rc = 1&lt;/P&gt;
&lt;P&gt;The certificates were created by different authorities (internal CA and Digicert)&lt;/P&gt;
&lt;P&gt;Both are .crt format. I have tried converting to PEM, this ends up as .cer format.&lt;/P&gt;
&lt;P&gt;The common names (CN) are the hostname of the WLC&lt;/P&gt;
&lt;P&gt;The WLC is in an SSO HA pair and running 8.3.133.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any pointers much appreciated&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 15:11:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/3322355#M112424</guid>
      <dc:creator>ashmead123</dc:creator>
      <dc:date>2021-07-05T15:11:28Z</dc:date>
    </item>
    <item>
      <title>Re: Webauth and Webadmin certificates fail to install on a WLC 5520</title>
      <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/3322388#M112425</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/340389"&gt;@ashmead123&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Did you follow some guide? Here on the forum we can see a lot of people with the same problem.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This guide looks very clear and updated. Take a look and let us know:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-0/configuration-guide/b_cg80/b_cg80_chapter_01001.html" target="_self"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-0/configuration-guide/b_cg80/b_cg80_chapter_01001.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 10:54:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/3322388#M112425</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2018-01-31T10:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: Webauth and Webadmin certificates fail to install on a WLC 5520</title>
      <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/3322404#M112426</link>
      <description>Hi Flavio&lt;BR /&gt;&lt;BR /&gt;Thanks for this, all of the guides recommend the use of OpenSSL. Is this application a necessity to get the certificate to install correctly?&lt;BR /&gt;Do you have a trusted link to download openSSL?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;Ashley</description>
      <pubDate>Wed, 31 Jan 2018 11:19:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/3322404#M112426</guid>
      <dc:creator>ashmead123</dc:creator>
      <dc:date>2018-01-31T11:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: Webauth and Webadmin certificates fail to install on a WLC 5520</title>
      <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/3322406#M112427</link>
      <description>&lt;P&gt;Sure. &amp;nbsp;Official web site. Go to the download tab.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.openssl.org/" target="_self"&gt;https://www.openssl.org/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 11:23:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/3322406#M112427</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2018-01-31T11:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: Webauth and Webadmin certificates fail to install on a WLC 5520</title>
      <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/3354391#M112428</link>
      <description>&lt;P&gt;I have now converted the cert files into .pem format.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I now get the following debug output. Is this related to the certificate chain? Currently the certificate is in the format:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-----BEGIN CERTIFICATE-----&lt;/P&gt;
&lt;P&gt;xxxx&lt;/P&gt;
&lt;P&gt;-----END CERTIFICATE-----&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;pki debug:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*TransferTask: Mar 24 10:20:28.443: [PA] tftp rc=0, pHost=10.201.192.131 pFilename=/WebAuth.pem&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; pLocalFilename=cert.p12&lt;/P&gt;
&lt;P&gt;*TransferTask: Mar 24 10:20:28.458: [PA] RESULT_STRING: TFTP receive complete... Installing Certificate.&lt;/P&gt;
&lt;P&gt;*TransferTask: Mar 24 10:20:28.458: [PA] RESULT_CODE:13&lt;/P&gt;
&lt;P&gt;*TransferTask: Mar 24 10:20:32.466: [PA] Adding cert (2128 bytes) with certificate key password.&lt;/P&gt;
&lt;P&gt;*TransferTask: Mar 24 10:20:32.466: [PA] Add WebAuth Cert: Adding certificate &amp;amp; private key using password&lt;BR /&gt;*TransferTask: Mar 24 10:20:32.466: [PA] Add ID Cert: Adding certificate &amp;amp; private key using password&lt;BR /&gt;*TransferTask: Mar 24 10:20:32.466: [PA] Add Cert to ID Table: Adding certificate (name: bsnSslWebauthCert) to ID table using password&lt;BR /&gt;*TransferTask: Mar 24 10:20:32.466: [PA] Add Cert to ID Table: Decoding PEM-encoded Certificate (verify: YES)&lt;BR /&gt;*TransferTask: Mar 24 10:20:32.466: [PA] Decode &amp;amp; Verify PEM Cert: Cert/Key Length was 0, so taking string length instead&lt;BR /&gt;*TransferTask: Mar 24 10:20:32.466: [PA] Decode &amp;amp; Verify PEM Cert: Cert/Key Length 2128 &amp;amp; VERIFY&lt;BR /&gt;*TransferTask: Mar 24 10:20:32.467: [PA] Decode &amp;amp; Verify PEM Cert: X509 Cert Verification return code: 0&lt;BR /&gt;*TransferTask: Mar 24 10:20:32.467: [PA] Decode &amp;amp; Verify PEM Cert: X509 Cert Verification result text: unable to get local issuer certificate&lt;BR /&gt;*TransferTask: Mar 24 10:20:32.467: [PA] Decode &amp;amp; Verify PEM Cert: Error in X509 Cert Verification at 0 depth: unable to get local issuer certificate&lt;BR /&gt;*TransferTask: Mar 24 10:20:32.467: [PA] Add Cert to ID Table: Error decoding (verify: YES) PEM certificate&lt;BR /&gt;*TransferTask: Mar 24 10:20:32.467: [PA] Add ID Cert: Error decoding / adding cert to ID cert table (verifyChain: TRUE)&lt;BR /&gt;*TransferTask: Mar 24 10:20:32.467: [PA] Add WebAuth Cert: Error adding ID cert&lt;BR /&gt;*TransferTask: Mar 24 10:20:32.467: [PA] RESULT_STRING: Error installing certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Mar 2018 10:52:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/3354391#M112428</guid>
      <dc:creator>ashmead123</dc:creator>
      <dc:date>2018-03-24T10:52:12Z</dc:date>
    </item>
    <item>
      <title>Re: Webauth and Webadmin certificates fail to install on a WLC 5520</title>
      <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/3354396#M112429</link>
      <description>&lt;P&gt;I think this link will help you:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/109597-csr-chained-certificates-wlc-00.html" target="_self"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/109597-csr-chained-certificates-wlc-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
      <pubDate>Sat, 24 Mar 2018 11:09:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/3354396#M112429</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2018-03-24T11:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: Webauth and Webadmin certificates fail to install on a WLC 5520</title>
      <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/3949225#M112430</link>
      <description>&lt;BLOCKQUOTE&gt;*TransferTask: Mar 24 10:20:32.467: [PA] Decode &amp;amp; Verify PEM Cert: X509 Cert Verification return code: 0&lt;BR /&gt;*TransferTask: Mar 24 10:20:32.467: [PA] Decode &amp;amp; Verify PEM Cert: X509 Cert Verification result text: unable to get local issuer certificate&lt;BR /&gt;*TransferTask: Mar 24 10:20:32.467: [PA] Decode &amp;amp; Verify PEM Cert: Error in X509 Cert Verification at 0 depth: unable to get local issuer certificate&lt;/BLOCKQUOTE&gt;&lt;P&gt;Looks like the file you try to import only contains the certificate of the WLC while it should contain the entire certificate chain, in this order: WLC, intermediate CA, root CA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 14:30:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/3949225#M112430</guid>
      <dc:creator>Etienne Buxin</dc:creator>
      <dc:date>2019-10-28T14:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: Webauth and Webadmin certificates fail to install on a WLC 5520</title>
      <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/3949625#M112431</link>
      <description>&lt;P&gt;Also try to upgrade the WLC software and then give a try again as 8.3.133.0 is already deffered from cisco.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Dont forget to rate helpful posts&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2019 06:02:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/3949625#M112431</guid>
      <dc:creator>Sandeep Choudhary</dc:creator>
      <dc:date>2019-10-29T06:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: Webauth and Webadmin certificates fail to install on a WLC 5520</title>
      <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4007063#M112432</link>
      <description>&lt;P&gt;Can you please tell me what you did to get this to work. I am experiencing the exact same issue. My cert is a .pem and&amp;nbsp; I am getting this error&amp;nbsp;&lt;STRONG&gt;%UPDATE-3-CERT_INST_FAIL: updcode.c:3686 Failed to install certificate. rc = 1.&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2020 16:35:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4007063#M112432</guid>
      <dc:creator>William Foster</dc:creator>
      <dc:date>2020-01-06T16:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: Webauth and Webadmin certificates fail to install on a WLC 5520</title>
      <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4007074#M112433</link>
      <description>&lt;P&gt;Actually to expand on my problem. I am not even able to TFTP the cert to the controller. I am getting a file transfer failed! I am certain that TFTP is not being blocked. However when I look at the log I see this below error.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;TransferTask: Jan 06 10:44:20.336: %UPDATE-3-CERT_INST_FAIL: updcode.c:3686 Failed to install certificate. rc = 1 so it does appear my issue is different.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2020 16:46:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4007074#M112433</guid>
      <dc:creator>William Foster</dc:creator>
      <dc:date>2020-01-06T16:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Webauth and Webadmin certificates fail to install on a WLC 5520</title>
      <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4007165#M112434</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/328158"&gt;@William Foster&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Actually to expand on my problem. I am not even able to TFTP the cert to the controller. I am getting a file transfer failed! I am certain that TFTP is not being blocked. However when I look at the log I see this below error.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;TransferTask: Jan 06 10:44:20.336: %UPDATE-3-CERT_INST_FAIL: updcode.c:3686 Failed to install certificate. rc = 1 so it does appear my issue is different.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Enable PKI debugs and try the transfer again then post the output here. Also make sure you include the full certificate chain in the PEM file, not only the WLC certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;debug pm pki enable&lt;BR /&gt;transfer download start&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Mon, 06 Jan 2020 19:37:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4007165#M112434</guid>
      <dc:creator>Etienne Buxin</dc:creator>
      <dc:date>2020-01-06T19:37:34Z</dc:date>
    </item>
    <item>
      <title>Re: Webauth and Webadmin certificates fail to install on a WLC 5520</title>
      <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4015565#M112435</link>
      <description>&lt;P&gt;Sorry for the delay in response. I was able to get this issue resolved. My cert was not formatted correctly. It had to be like below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;------BEGIN CERTIFICATE------&lt;BR /&gt;*End Entity Certificate Content*&lt;BR /&gt;------END CERTIFICATE------&lt;BR /&gt;------BEGIN CERTIFICATE------&lt;BR /&gt;*Intermediate CA Certificate Content*&lt;BR /&gt;------END CERTIFICATE--------&lt;BR /&gt;------BEGIN CERTIFICATE------&lt;BR /&gt;*Root CA Certificate Content*&lt;BR /&gt;------END CERTIFICATE------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once I had the cert in that format then it downloaded the cert. So it is good to know if the cert is not correct then the WLC will not even download the cert.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 18:29:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4015565#M112435</guid>
      <dc:creator>William Foster</dc:creator>
      <dc:date>2020-01-21T18:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: Webauth and Webadmin certificates fail to install on a WLC 5520</title>
      <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4016141#M112436</link>
      <description>&amp;gt;&amp;gt; So it is good to know if the cert is not correct then the WLC will not even download the cert.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;It will download the cert but it will discard it if not well formatted &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 22 Jan 2020 13:11:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4016141#M112436</guid>
      <dc:creator>Etienne Buxin</dc:creator>
      <dc:date>2020-01-22T13:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: Webauth and Webadmin certificates fail to install on a WLC 5520</title>
      <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4016228#M112437</link>
      <description>Yeah... that is what happens if there is anything wrong with a cert that gets uploaded.  &lt;BR /&gt;</description>
      <pubDate>Wed, 22 Jan 2020 14:10:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4016228#M112437</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2020-01-22T14:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: Webauth and Webadmin certificates fail to install on a WLC 5520</title>
      <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4129186#M112438</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326193"&gt;@Scott Fella&lt;/a&gt;&amp;nbsp;so what does someone do when a cert is uploaded, but rejected?&amp;nbsp; How do I dind out WHY it was rejected?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a correctly chained PEM certificate file.&amp;nbsp; It is accepted by the transfer download process and installed.&amp;nbsp; The CSR was generated by the CLI on the WLC (2504, runing 8.5) and it was signed by a Microsoft CA.&lt;/P&gt;&lt;P&gt;When I install this certificate, it blindly accepts it, makes me restart the WLC (really, really annoying having 2-3 mins of outage every time I "experiment") then no longer responds on port 443 for HTTPs for webadmin.&lt;/P&gt;&lt;P&gt;I am forced to generate a self-signed cert again to get access to the web GUI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some more debug help from the WLC would be most welcome here.&amp;nbsp; Is there a way to peek under the hood to actually see detail on why it isn't working?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Aug 2020 11:32:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4129186#M112438</guid>
      <dc:creator>ROB LYLE</dc:creator>
      <dc:date>2020-08-02T11:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: Webauth and Webadmin certificates fail to install on a WLC 5520</title>
      <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4129189#M112439</link>
      <description>I’m not understanding what is wrong?  Web admin and web Auth certainly are uploaded to the controller in two different locations. The cert is uploaded so it’s seems to be fine, my question would be, is there a dns entry defined and is it pointing to the right ip?  Webauth points to the VIP so your fqdn needs to resolve to the VIP. The management ip resolves to the fqdn you specified on the cert. I have only used OpenSSL to generate certificates, never on the controller. Also make sure you flush out your browser dns entries after uploading the cert. &lt;BR /&gt;</description>
      <pubDate>Sun, 02 Aug 2020 11:51:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4129189#M112439</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2020-08-02T11:51:09Z</dc:date>
    </item>
    <item>
      <title>Re: Webauth and Webadmin certificates fail to install on a WLC 5520</title>
      <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4129193#M112440</link>
      <description>Gah! A quick "debug pm pki enable" made me notice one error.&lt;BR /&gt;&lt;BR /&gt;transfer download datatype webauthcert&lt;BR /&gt;changed to ...&lt;BR /&gt;transfer download datatype webadmincert&lt;BR /&gt;&lt;BR /&gt;I was downloading my webadmin signed certificate to the webauth location. Strange that it accepted that, as the CSR was generated for webadmin via the CLI.</description>
      <pubDate>Sun, 02 Aug 2020 12:03:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4129193#M112440</guid>
      <dc:creator>ROB LYLE</dc:creator>
      <dc:date>2020-08-02T12:03:45Z</dc:date>
    </item>
    <item>
      <title>Re: Webauth and Webadmin certificates fail to install on a WLC 5520</title>
      <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4129202#M112441</link>
      <description>Well it’s a cert and you can use it on either. The cert is not valid unless it can be resolved. &lt;BR /&gt;</description>
      <pubDate>Sun, 02 Aug 2020 12:47:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4129202#M112441</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2020-08-02T12:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: Webauth and Webadmin certificates fail to install on a WLC 5520</title>
      <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4129206#M112442</link>
      <description>If I only understood how the WLC matches private keys with certificates, then I'd agree. The WLC CLI interface specifically asks for "webadmin" and "webauth" certificates implying that different certificates are needed for each, with private keys stored in different places.&lt;BR /&gt;&lt;BR /&gt;On a slightly unrelated (probably) note, how do I undo this command:&lt;BR /&gt;&lt;BR /&gt;(Cisco Controller) &amp;gt;config certificate use-device-certificate webadmin&lt;BR /&gt;&lt;BR /&gt;There is no "enable" or "disable" here and I can't find any documentation online about what this actually does. I am guessing it forces use of a builtin Cisco manufacturer certificate and would be undone when I install my own 3rd party certificate or generate a self-signed local cert? Total guess however as the Cisco Wireless Controller Configuration Guide, Release 8.5 (b_cg85.pdf) doesn't tell me anything. Sniff.&lt;BR /&gt;</description>
      <pubDate>Sun, 02 Aug 2020 13:11:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4129206#M112442</guid>
      <dc:creator>ROB LYLE</dc:creator>
      <dc:date>2020-08-02T13:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: Webauth and Webadmin certificates fail to install on a WLC 5520</title>
      <link>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4129237#M112443</link>
      <description>You need to go on the GUI and generate a self-signed. One you generate a self signed or upload a new cert, the wlc doesn’t keep any other cert for that purpose. &lt;BR /&gt;</description>
      <pubDate>Sun, 02 Aug 2020 16:23:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/webauth-and-webadmin-certificates-fail-to-install-on-a-wlc-5520/m-p/4129237#M112443</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2020-08-02T16:23:09Z</dc:date>
    </item>
  </channel>
</rss>

